SSH

SSH Key Fingerprint

Calculate SHA256 and legacy MD5 fingerprints from an OpenSSH public key

Security & Auth
πŸ”’ 100% client-side β€” your data never leaves this page
Maintained by Evanβ€’Updated: September 30, 2026
OPENSSH PUBLIC KEY

Checks one public-key line and its field structure, not ownership or trust. Private keys are not accepted.

Key summary

SHA256, MD5, key type, bits/curve, and comment will appear here.

About this tool

SSH Key Fingerprint reads one OpenSSH public-key or authorized_keys line up to 1 MB. It recognizes RSA, DSA, Ed25519, NIST P-256/P-384/P-521 ECDSA and OpenSSH Ed25519/P-256 security-key formats. It checks declared and embedded types, required fields, positive minimal mpints, supported curve names, public-key byte lengths and complete blob consumption. SHA256 and legacy MD5 cover only the binary blob. Quoted authorization options are skipped when selecting the key; the displayed public-key material omits those restrictions and must not replace an existing authorized_keys entry. These are format checks, not proof of key ownership, valid elliptic-curve points, subgroup properties or trust. Private keys, OpenSSH certificates and multiple lines are rejected.

Scenario Recipes

01

Compare a deployment key without dropping authorization restrictions

Goal: Confirm the key identity while preserving its authorized_keys policy

  1. Paste one public-key or authorized_keys line.
  2. Compare its SHA256 fingerprint through a separate trusted channel.
  3. Keep the original authorization options when approving or editing the entry; use the host-key trust process for server host keys.

Result: A compared public-key identity with its original access restrictions preserved.

Production Snippets

Compare a public fixture with ssh-keygen

text

ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICZ91s1xQO72WbF5R/kzTMNLo8c5UJfJDRAMWWHN7bFv round6-public-test
Expected SHA256:svyAwCPWAbBuFzNxMRwUxCAVabdTvyHK5IKI3RkjcWU
Save as fixture.pub, then run: ssh-keygen -lf fixture.pub
Changing the comment does not change the fingerprint. A blob containing only ssh-ed25519 with no 32-byte key must fail.

Frequently Asked Questions

Which SSH public-key formats are accepted?

Use one OpenSSH RSA, DSA, Ed25519, NIST ECDSA or supported OpenSSH security-key public line. An authorized_keys option list may precede it, including quoted command values. Multi-line lists and certificates are not supported.

Does the fingerprint include the comment?

No. OpenSSH fingerprints hash the binary key blob; the trailing user@host comment is display metadata.

Why are SHA256 and MD5 both shown?

SHA256 is the modern OpenSSH default, while MD5 helps compare older inventories and console output.

Can it read a private key?

No. Private-key blocks are explicitly rejected and are not needed to calculate a public-key fingerprint.

Are OpenSSH certificates supported?

No. Certificate key types contain additional signed fields and are intentionally rejected by this public-key parser.

Is the key uploaded?

No. Base64 decoding, blob validation, bit inspection, SHA256, and MD5 calculation all run locally.

Can I replace authorized_keys with the displayed public-key line?

No. The displayed material omits from, command, restrict and other authorization options. Keep the original restricted entry and compare the fingerprint separately. Host keys belong to the host-trust workflow, not a user authorized_keys file.

Does a fingerprint prove the key is trusted or mathematically valid?

No. The tool checks field structure and fingerprints bytes. It does not prove private-key possession, evaluate curve points or DSA groups, or establish a trusted identity. Compare SHA256 through a separate trusted channel.

Keep browsing